hhhai
hhhai is a security researcher credited with 56 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #107 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 55 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 17 of their findings (30%). Other recurring categories include Missing Authorization, SQL Injection. The average CVSS score across these disclosures is 6.6, peaking at 9.8. Severity breakdown: 2 critical and 25 high.
The most affected software includes WP Job Portal (3), Active Woot Products Tables… (2), EventPrime (2), across 51 distinct plugins, themes and core versions in total.
50 of the 56 disclosed issues have a vendor fix, while 6 remain unpatched. The most severe finding, "WebinarIgnition – Live, Automated & Evergreen Webinar System also for WooCommerce < 4.08.253 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.
#107
of 3,515 researchers
56
51
6.6
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C